REDLEGG BLOG

Emergency Vulnerability Bulletin - 09/30/22

9/30/22 5:18 PM  |  by RedLegg Blog

Atlassian Bitbucket Server and Data Center Vulnerability

Identifier: CVE-2022-36804

Exploit or POC: Yes (Actively Being Exploited)

Update: https://jira.atlassian.com/browse/BSERV-13438

Description: CVE-2022-36804 allows for arbitrary code execution by transmitting malicious HTTP requests. To successfully exploit this vulnerability read permissions to a private or public Bitbucket repository is required.

Mitigation recommendation: Patching is currently the only method of mitigation

RedLegg Action: None at this time.

Get Blog Updates

Related Articles

Emergency Vulnerability Bulletin - 11/30/22 threat intel, 96bravo

Emergency Vulnerability Bulletin - 11/30/22

About: RedLegg will occasionally communicate vulnerabilities released outside the usual release schedule to provide ...
Emergency Vulnerability Bulletin - 11/29/22 threat intel, 96bravo

Emergency Vulnerability Bulletin - 11/29/22

Oracle Fusion Middleware Unspecified Vulnerability Identifier: CVE-2022-35587 Exploit or POC: Yes (Actively Being ...
Critical Security Vulnerabilities Bulletin